Skip to content

Privacy

What we hold about you, why we hold it, where it lives and how to make us delete it. Written from the actual database rather than from a template, so it says what is true and not what is customary.

Who is responsible

NoMore404, Amsterdam, the Netherlands. For the data we hold about you as our customer, we are the controller. For the monitoring you configure, you are the controller and we act on your instructions as your processor. That relationship is set out in our data processing agreement, which we will sign on request.

What we hold, and why

Listed by what it is rather than by category, because "account data" is not something you can check and a list is.

What Why Basis
Your email address Identifies your account, and receives verification and password mail Contract
Your password Signing in. Stored as an Argon2 hash, which cannot be turned back into your password Contract
Two-factor secret and recovery codes Only if you switch two-factor on Contract
Last sign-in time Account security, and telling an abandoned account from a quiet one Legitimate interest
Organisation name, country, timezone Invoicing, working out the right tax, and knowing when it is the middle of your night Contract
Alert destinations: email addresses, phone numbers, webhook URLs Sending the alerts you asked for. Webhook and chat URLs are encrypted, because such a URL lets whoever holds it post as you Contract
Language and theme preference Showing the interface and your alerts the way you chose Contract
Stripe customer and subscription identifiers Linking your account to your subscription. We never see or store your card number Contract

What monitoring produces is not about you. A check result is a monitor number, a probe number, a timestamp, a status, a response time and an error class. There is no person in it.

What we do not do

Cookies

One cookie, set when you sign in, holding which account you are using and nothing else. It is signed so it cannot be edited, and marked Secure so it only travels over HTTPS. A second, short-lived one exists during a half-finished login.

Both are strictly necessary to sign you in, which is why there is no cookie banner asking you to accept anything. There is nothing here to consent to.

Where it lives, and who else touches it

Everything about you is stored in the Netherlands, at TransIP, who also send our mail. Three other companies are involved, each for one job:

Stripe Payments Europe, Ireland
Payments and invoices. They handle your card so that we never do.
Independent hosting providers, worldwide
The probes that do the checking, deliberately spread across continents and across providers, because a failure confirmed by the same company on the same continent confirms our blind spot rather than your outage. A probe is given a hostname to check and reports whether it answered. It holds nothing about you and cannot reach our database. If you give an HTTP monitor a username and password or a token, the probes checking it do hold that, because they are what sends it, and keep it on their own disk so a restart does not interrupt the check.

When we look at it ourselves

One operator can read your organisation's data in order to run and support the service: your monitors, your incidents, who is on your team, and which plan you are on. Not your passwords, which are hashed and cannot be read by anybody, and not your card, which only Stripe ever holds.

Every one of those views is written down as it happens: which organisation was looked at, by whom, and when. We keep that log for a year, and it outlives the account it is about: a record of who read your data is no use if it goes when the data does. The page that does the looking cannot change anything. Ask us through contact and we will send you your organisation's entries.

How long we keep it

Individual check results
90 days
Hourly summaries, incidents and the record of the alerts we sent, which is what your graphs, reports and incident history are drawn from
Free and Starter: 90 days
Pro and Business: 1 year
Your account and everything you configured
Until you delete it
Invoices
7 years, required by Dutch tax law

When those periods are up, we delete it, checked once a day. Moving to a plan that keeps less deletes whatever is older than the new plan's period on the next day's run.

Our servers' logs record the IP address each request came from. They stay on the servers that write them, are copied nowhere else, and go when those servers are replaced, which every update of the service does. That is not a fixed number of days: until the next update, a log is only trimmed by size.

Your rights

You can ask us for a copy of what we hold, correct it, delete it, restrict what we do with it, object to processing based on legitimate interest, or ask for it in a portable form. Where we ever rely on your consent, you can withdraw it at any time, and that does not affect anything done before you did.

Write to us and we will answer within a month. No forms and no identity theatre: if you can sign in, that is who you are.

If we get it wrong, you can complain to the Autoriteit Persoonsgegevens, the Dutch data protection authority. We would rather you told us first, but that is your right and not our permission to give.

Changes to this page

If we add a company that handles your data, or start using it for something new, we will tell you before it happens rather than quietly updating this page and dating it. A change you have to notice for yourself is not a notice.

11 September 2026: added "When we look at it ourselves". We built an operator view of the platform, so for the first time somebody here can read your data without you asking us to. It is logged, and now it is written down.

Questions, or a request about your data: contact us.